Brian Johnson
7 Minute Security
7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
7MS #479: A Prelude to PwnTown 06.08.2021 7:03
Hey friends, today we're talking about a new security training offering 7MinSec has created called Light Pentest LITE - Live Interactive Training Experience . It's a 3-day course (with each class session being 3 hours long) consisting of live (via Zoom), hands-on, instructor-led sessions that are focused on teaching you how to find, exploit and defend against common Active Directory weaknesses! C...
7MS #478: Password Cracking in the Cloud - Part 4 29.07.2021 37:18
Hey friends, today we're continuing our discussion of password cracking by sharing some methodology that has helped us get a high cred yield, and some tips on taking cracked passwords from multiple sources and Frankensteining them into a beautiful report for your customer. For some background, when 7MS started as a biz, we used to crack passwords in Paperspace but invested in an on-prem crackin...
7MS #477: Cobalt Strike for Newbs 21.07.2021 38:07
Today we're talking about Cobalt Strike for newbs - including how to get it up and running, as well as some tools that will help you generate beacons while evading EDR at the same time! Some helpful things mentioned in today's episode: Wherever you spin up your CS instance, it's probably a good idea to lock down the firewall to only specific IPs. With Digital Ocean, I found this article helpful....
7MS #476: Tales of Pentest Pwnage - Part 28 16.07.2021 25:59
**STOP!** If you didn't listen to [last week's episode](https://7ms.us/7ms-475-tales-of-internal-network-pentest-pwnage-part-27/) you might want to, since this was a two-part tale of pwnage. Either way I'll get you up to speed and talk about why this was (of course) one of my favorite pentests ever.
7MS #475: Tales of Internal Network Pentest Pwnage - Part 27 08.07.2021 56:27
Yeahhhhhh! Today's another fun tale of pentest pwnage, including: The importance of starting your pentest with an AD account that actually has access to...ya know...stuff The importance of starting your pentest plugged into a network that actually has...you know...systems connected to it! This BHIS article is awesome for finding treasures in SMB shares PowerUpSQL audits are a powerful way to get...
7MS #474: Password Cracking in the Cloud - Part 3 30.06.2021 46:12
Hey friends! Today we're dusting off an old mini-series about password cracking in the cloud (check out part 1 and part 2 ) and sharing some awesome info on building a monster of a cracking rig in AWS! One reason we haven't talked about password cracking in the cloud in a while is because back in winter of 2019 I built baby's first password cracking . Unfortunately, this week, Hashy (the name...
7MS #473: Interview with Nikhil Mittal 24.06.2021 51:09
Hey everybody! Today Joe and I sat down with Nikhil Mittal of Pentester Academy and Altered Security to talk about a whole slew of fun security topics: How Nikhil first got involved in Pentester Academy Nikhil's hacker origin story How does Nikhil feel about his tools being used by baddies? What security tools/defenses would be good for SMBs to focus on? Active Directory security - is all...
7MS #473: Interview with Nikhil Mittal 24.06.2021 51:09
Hey everybody! Today Joe and I sat down with Nikhil Mittal of Pentester Academy and Altered Security to talk about a whole slew of fun security topics: How Nikhil first got involved in Pentester Academy Nikhil's hacker origin story How does Nikhil feel about his tools being used by baddies? What security tools/defenses would be good for SMBs to focus on? Active Directory security - is all...
7MS #472: Interview with Christopher Fielder 16.06.2021 52:24
Today our good pal Christopher Fielder from Arctic Wolf is back for an interview three-peat ! He joins Joe "The Machine" Skeen (a.k.a. Gh0sthax ) and I to talk about all things ransomware, including: How the Colonial Pipeline incident may have started from a weak VPN cred with no MFA . Silver lining (?) - they got some of the $ back . Was the federal government's response good enough? What ...
7MS #471: Cyber News - Ransomware Should Run Somewhere Edition 09.06.2021 1:02:05
Hey everybody, happy June! Our pal Joe is back to cover some great security stories with us, including: Peloton's leaky API Some Colonial Pipeline discussion ( story 1 , story 2 ) Amazon Sidewalk doesn't really share your Internet connection with neighbors/strangers. The Hacker News article doesn't do an awesome job of clearing that up either.
7MS #470: First Impressions of Meraki Networking Gear 02.06.2021 36:32
Today we're doing something new - a first impressions episode of Meraki networking gear. Note: this is not a sponsored episode, but rather a follow up to episode #460 where I talked about throwing all my UniFi gear into the ocean and replacing it with Meraki gear. At the end of that episode I asked if anybody was interested in a "first impressions" of the gear, and it turns out (at least 6)...
7MS #469: Interview with Philippe Humeau of CrowdSec 26.05.2021 48:25
Hey friends! Today we're talking with Philippe Humeau, CEO of CrowdSec , which is " an open-source massively multiplayer firewall able to analyze visitor behavior & provide an adapted response to all kinds of attacks. It also leverages the crowd power to generate a global IP reputation database to protect the user network ." I came into this interview not knowing much at all about CrowdSec, so I...
7MS #468: Eating the Security Dog Food - Part 3 20.05.2021 24:55
Today we continue the series on eating your own security dog food ! Specifically, we talk about: Keeping a log and procedure for sanitizing systems Keeping a log and procedure for provisioning systems A big "gotcha" to be aware of when using Windows system dropboxes - make sure your Windows user account doesn't expire, because Splashtop doesn't have any way to update it! To prevent this, set th...
7MS #467: How to Succeed in Business Without Really Crying - Part 9 12.05.2021 55:39
Hey everybody! I stayed in a hotel for the first time in over a year and boy oh boy...I hope I didn't get COVID from the bedsheets! Anyhow, on that journey I thought of some things that I think will help your business on the marketing/project management/sales side to be more successful and less annoying. DISCLAIMER: I have no formal training in these areas, but I've been on both sides of the table...
7MS #466: Attacking and Defending Azure AD Cloud (CARTP) 05.05.2021 1:00:44
Welp, I need another security certification like I needed a bunch to the retinas, but even after all the fun (and pain) of CRTP I couldn't help but sign up for the maiden voyage of Attacking and Defending Azure AD Cloud - a.k.a. CARTP . This cert comes to us from our friends over at Pentester Academy , and is all about pwning things in Azure AD which is mostly new ground for me. I this episode...
7MS #465: Cyber News - The FBI Might Be Getting Into the IR Biz Edition 28.04.2021 53:24
Hey friends! Today Joe "The Machine" Skeen (a.k.a. Gh0sthax ) and I talk about some of our favorite news stories, including: FBI removes hacker back doors NSA: 5 security bugs under active nation-state cyberattack Ubiquiti is accused of covering up a 'catastrophic' data breach — and it's not denying it . On a side note, enjoy our podcast about how we lost our love for Ubiquiti a while back: 7M...
7MS #464: Interview with Christopher Fielder of Arctic Wolf 22.04.2021 50:58
Today our friend Christopher Fielder of Arctic Wolf joins us on the show again (check out his first appearance in episode #444 - this time to talk about the security journey, and how to start out in your "security diapers" and mature towards a stronger infosec program. Specifically, we talk about: When the company has one person in charge of IT/security, how can you start taking security serio...
7MS #463: DIY Pentest Dropbox Tips - Part 5 14.04.2021 37:57
In the last two episodes of this series ( #449 and #450 ) we've been diving into how to not only speed up the process of spinning up a DIY pentest dropbox, but how to automate nearly the entire build process! In today's episode we talk specifically about how to streamline the Windows 10 build process. As previously mentioned, this article is awesome for creating a core Win 10 answer file tha...
7MS #462: Pentesting with the Hak5 Key Croc 07.04.2021 37:39
Today we talk through our first engagement using Hak5 Key Croc to steal and exfil data. In the past, my internal monologue when a new Hak5 toy is released sounds like this: "I certainly don't need another Hak5 doo-dad! The last one didn't ever work that great, and ended up in a drawer full of past Hak5 doo-dads that didn't work that great." "Whaaaaat? A new cool and hip video for the INSERT_CATC...
7MS #461: Tales of Internal Network Pentest Pwnage - Part 26 31.03.2021 47:58
OK I probably say this every time, but I'm gonna say it again: this tale of pwnage is my one of my favs - and not because of the tools/tradecraft, but because of why the company needed our help in the first place. I think I'd file this under the category of "rescue and recovery mission" more than a pentest, but it was a total blast. I also cover a few tangents, including how COVID shot #2 gave m...
7MS #460: Why I'm Throwing My UniFi Gear Into the Ocean 24.03.2021 40:51
Hey friends! Warning: this is not a "typical" 7MS episode where we try hard to deliver some level of security value. Instead, today is a big, fat, crybaby, first-world problems whine-fest about how I used to love my UniFi gear for many years, but then a few weeks ago I hit unhealthy levels of rage while working with it...and subsequently completely ripped it all out of the wall and threw i...
7MS #459: Cyber News - Microsoft Exchange Makes the World Cry Edition 17.03.2021 1:03:19
Happy mid-March! Our good pal Gh0sthax joins us today for another hot dish of cyber news! Stories include: Microsoft Exchange cyber attack - Hacker News has a nice what we know so far story, but things have evolved really fast, so make sure you check Microsoft's primary advisory , the script to run on local servers and newer updates such as the recent one-click remediation for unsupport...
7MS #458: Interview with Tanya Janca 11.03.2021 59:14
Today we're super excited to share a featured interview with Tanya Janca of WeHackPurple ! Tanya has been in software development from the moment she was of legal age to work in Canada - beginning by working with some huge companies (Nokia/Adobe) before falling in love with application security and eventually starting a company of her own. Gh0sthax and I sat down with Tanya over Zoom to discus...
7MS #457: Tales of Internal Network Pentest Pwnage - Part 25 04.03.2021 31:35
Hi! This episode of pentest pwnage is a fun one because it was built for speeeeeeeeeeeeeeeed . Here's some of the things we're doing/running when time is of the essence: Get a cmd.exe spun up in the context of your AD user account: runas /netonly /user:samplecompany\billybob "C:\windows\system32\cmd.exe" Then get some important info in PowerView : Get-DomainUser -PreAuthNotRequired - find AD us...
7MS #456: Certified Red Team Professional - Part 4 25.02.2021 56:56
Hello friends! Today, Joe ( Gh0sthax ) and I complete our series on CRTP - Certified Red Team Professional - a really awesome pentesting training and exam based squarely on Microsoft tools and tradecraft. Specifically, Joe and I talk about: We don't think the training/exam is for beginners, despite how its advertised Both the lab PDF and PowerPoint have their own quirks - which may ultimatel...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.